Infosecurity-Magazine HollowFrame Loader and Matryoshka Malware Target Law Firm with Advanced Techniques
Article Content
- •The HollowFrame loader uses a fake Python DLL to bypass Microsoft Defender.
- •The attack targets a law firm, employing spear-phishing to initiate the intrusion.
- •Matryoshka malware features two variants, complicating detection and enhancing persistence.
A sophisticated cyberattack has been identified, targeting a law firm with a new Go-based loader named HollowFrame and a Rust-based malware family called Matryoshka. The attack commenced with a spear-phishing email leading to an encrypted archive containing a malicious Windows Shortcut file. Upon execution, the malware escalated privileges, disabled Microsoft Defender protections, and downloaded additional payloads. HollowFrame employs DLL sideloading techniques using a counterfeit Python runtime to evade detection. The Matryoshka backdoor features two variants, one utilizing HTTP and the other leveraging a private GitHub repository for command and control. The attack's modular design complicates detection and attribution, posing a significant threat to the affected organization. Blackpoint Cyber has recommended monitoring for unexpected GitHub API connections as part of their mitigation strategy.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track HollowFrame in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's Hybrid Warfare Threatens EU Elections As elections approach in the EU, Russian operations are intensifying, employing disinformation, cyberattacks, and sabotage to undermine democracies. Security experts warn that these actions extend beyond Ukraine, targeting multiple EU nations. Estonian Defense Minister Hanno Pevkur highlighted the imminent elections…